Out-of-bounds write in Linux kernel - CVE-2026-74649

 

Out-of-bounds write in Linux kernel - CVE-2026-74649

Published: August 24, 2026


Vulnerability identifier: #VU144871
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74649
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write out of bounds or disclose sensitive information.

The vulnerability exists due to out-of-bounds write in the OnAuthClient() shared-key authentication handler when processing a malformed WLAN_EID_CHALLENGE element during shared-key authentication. A remote attacker can send a specially crafted wireless authentication frame to write out of bounds or disclose sensitive information.

The issue is reachable over the air before association.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74649

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins